このドキュメントでは、Firepower Management Center(FMC)で管理アクセス用の外部2要素認証を設定するために必要な手順について説明します。
次の項目に関する知識があることが推奨されます。
このドキュメントの情報は、特定のラボ環境にあるデバイスに基づいて作成されたものです。このドキュメントで使用するすべてのデバイスは、クリアな(デフォルト)設定で作業を開始しています。本稼働中のネットワークでは、各コマンドによって起こる可能性がある影響を十分確認してください。
FMC管理者はISEサーバに対して認証を行い、プッシュ通知の形式で追加の認証がDuo Authentication Proxyサーバによって管理者のモバイルデバイスに送信されます。

設定を完了するには、次のセクションを考慮してください。
ステップ 1:System > Users > External Authenticationの順に移動します。 外部認証オブジェクトを作成し、認証方式をRADIUSに設定します。 Default User RoleでAdministratorが選択されていることを確認します。


Saveをクリックし、Applyをクリックします(警告は無視されます)。

ステップ 2 System > Users > Usersの順に移動します。 ユーザを作成し、Authentication Method as Externalにチェックマークを付けます。

ステップ 3Duo Authentication Proxy Serverをダウンロードしてインストールします。
Windowsマシンにログインし、Duo Authentication Proxy Serverをインストールします。
シスコでは、少なくとも1つのCPU、200 MBのディスク領域、および4 GBのRAMを搭載したシステムを使用することを推奨しています。
ステップ 4authproxy.cfgファイルを設定します。
このファイルをNotepad++やWordPadなどのテキストエディタで開きます。
authproxy.cfgファイルを編集し、次の設定を追加します。
[radius_client]
host=10.197.223.23 Sample IP Address of the ISE server
secret=cisco Password configured on the ISE server in order to register the network device
FMCのIPアドレスは、RADIUS秘密鍵とともに設定する必要があります。
[radius_server_auto]
ikey=xxxxxxxxxxxxxxx
skey=xxxxxxxxxxxxxxxxxxxxxxxxxxx
api_host=api-xxxxxxxx.duosecurity.com
radius_ip_1=10.197.223.76 IP of FMC
radius_secret_1=cisco Radius secret key used on the FMC
failmode=safe
client=radius_client
port=1812
api_timeout=
ikey、skey、api_hostの各パラメータを必ず設定してください。これらの値を取得するには、Duoアカウント(Duo Admin Login)にログインし、アプリケーション>アプリケーションの保護に移動します。次に、RADIUS認証アプリケーションを選択します。

ステップ 5Duo Security Authentication Proxy Serviceを再起動します。ファイルを保存し、WindowsマシンのDuoサービスを再起動します。
Windowsサービスコンソール(services.msc)を開きます。 サービスのリストでDuo Security Authentication Proxy Serviceを見つけて、Restartをクリックします。

ステップ 1:Administration > Network Devicesの順に移動します。Addをクリックして、ネットワークデバイスを設定します。

authproxy.cfgの* Shared Secretの説明に従って、共有秘密を設定します。

ステップ 2Administration > Identitiesの順に移動します。 Addをクリックして、IDユーザを設定します。

ステップ 1:ユーザー名を作成し、デバイス上でDuo Mobileをアクティブにします。
Duo Cloud管理Webページでユーザーを追加します。 Users > Add Usersの順に移動します。

ステップ 2 コードの自動生成。
ユーザの電話番号を追加します。


Activate Duo Mobileの順に選択します。

図に示すように、Duo Mobile Activation Codeの生成を選択します。

図に示すように、Send Instructions by SMSを選択します。

SMSのリンクをクリックすると、Duoアプリがデバイス情報セクションのユーザアカウントにリンクします。

ここでは、設定が正常に動作していることを確認します。
ステップ 1: ISEユーザIDページで追加したユーザクレデンシャルを使用してFMCにログインします。2要素認証(2FA)のエンドポイントでDuoプッシュ通知を受信する必要があります。 承認すると、FMCがログインします。

ステップ 2 ISEサーバで、Operations > RADIUS > Live Logsの順に移動します。 FMCで認証に使用するユーザ名を検索し、detailカラムの下のdetail authentication reportを選択します。認証が成功したかどうかを確認する必要があります。

このセクションでは、設定のトラブルシューティングに役立つ追加情報を提供します。
不正なクレデンシャルが入力され、ISEサーバによって認証が拒否された場合にスニペットをログに記録します。
2019-08-04T18:54:17+0530 [DuoForwardServer (UDP)] Sending request from 10.197.223.76 to radius_server_auto 10.197.223.76 is the IP of the FMC
2019-08-04T18:54:17+0530 [DuoForwardServer (UDP)] Received new request id 4 from ('10.197.223.76', 34524)
2019-08-04T18:54:17+0530 [DuoForwardServer (UDP)] (('10.197.223.76', 34524), 4): login attempt for username u'cpiplani'
2019-08-04T18:54:17+0530 [DuoForwardServer (UDP)] Sending request for user u'cpiplani' to ('10.197.223.23', 1812) with id 199
2019-08-04T18:54:17+0530 [RadiusClient (UDP)] Got response for id 199 from ('10.197.223.23', 1812); code 3 10.197.223.23 is the IP of the ISE Server.
2019-08-04T18:54:17+0530 [RadiusClient (UDP)] (('10.197.223.76', 34524), 4): Primary credentials rejected - No reply message in packet
2019-08-04T18:54:17+0530 [RadiusClient (UDP)] (('10.197.223.76', 34524), 4): Returning response code 3: AccessReject
2019-08-04T18:54:17+0530 [RadiusClient (UDP)] (('10.197.223.76', 34524), 4): Sending response
ISEサーバで、Operations > RADIUS > Live Logsの順に移動し、認証の詳細を確認します。
ISEおよびDuoで正常に認証されたログのスニペット:
2019-08-04T18:56:16+0530 [DuoForwardServer (UDP)] Sending request from 10.197.223.76 to radius_server_auto
2019-08-04T18:56:16+0530 [DuoForwardServer (UDP)] Received new request id 5 from ('10.197.223.76', 34095)
2019-08-04T18:56:16+0530 [DuoForwardServer (UDP)] (('10.197.223.76', 34095), 5): login attempt for username u'cpiplani'
2019-08-04T18:56:16+0530 [DuoForwardServer (UDP)] Sending request for user u'cpiplani' to ('10.197.223.23', 1812) with id 137
2019-08-04T18:56:16+0530 [RadiusClient (UDP)] Got response for id 137 from ('10.197.223.23', 1812); code 2 <<<< At this point we have got successful authentication from ISE Server.
2019-08-04T18:56:16+0530 [RadiusClient (UDP)] http POST to https://api-f754c261.duosecurity.com:443/rest/v1/preauth
2019-08-04T18:56:16+0530 [duoauthproxy.lib.http._DuoHTTPClientFactory#info] Starting factory <_DuoHTTPClientFactory: https://api-f754c261.duosecurity.com:443/rest/v1/preauth>
2019-08-04T18:56:17+0530 [HTTPPageGetter (TLSMemoryBIOProtocol),client] (('10.197.223.76', 34095), 5): Got preauth result for: u'auth'
2019-08-04T18:56:17+0530 [HTTPPageGetter (TLSMemoryBIOProtocol),client] Invalid ip. Ip was None
2019-08-04T18:56:17+0530 [HTTPPageGetter (TLSMemoryBIOProtocol),client] http POST to https://api-f754c261.duosecurity.com:443/rest/v1/auth
2019-08-04T18:56:17+0530 [duoauthproxy.lib.http._DuoHTTPClientFactory#info] Starting factory <_DuoHTTPClientFactory: https://api-f754c261.duosecurity.com:443/rest/v1/auth>
2019-08-04T18:56:17+0530 [duoauthproxy.lib.http._DuoHTTPClientFactory#info] Stopping factory <_DuoHTTPClientFactory: https://api-f754c261.duosecurity.com:443/rest/v1/preauth>
2019-08-04T18:56:30+0530 [HTTPPageGetter (TLSMemoryBIOProtocol),client] (('10.197.223.76', 34095), 5): Duo authentication returned 'allow': 'Success. Logging you in...'
2019-08-04T18:56:30+0530 [HTTPPageGetter (TLSMemoryBIOProtocol),client] (('10.197.223.76', 34095), 5): Returning response code 2: AccessAccept <<<< At this point, user has hit the approve button and the authentication is successful.
2019-08-04T18:56:30+0530 [HTTPPageGetter (TLSMemoryBIOProtocol),client] (('10.197.223.76', 34095), 5): Sending response
2019-08-04T18:56:30+0530 [duoauthproxy.lib.http._DuoHTTPClientFactory#info] Stopping factory <_DuoHTTPClientFactory: https://api-f754c261.duosecurity.com:443/rest/v1/auth>
| 改定 | 発行日 | コメント |
|---|---|---|
3.0 |
02-Jun-2026
|
スペル、文法、間隔などが更新されました。 |
2.0 |
15-Jun-2023
|
PIIを削除。
代替テキストが追加されました。
タイトル、概要、SEO、機械翻訳、スタイル要件、フォーマットを更新。 |
1.0 |
20-Aug-2019
|
初版 |